Kimo
Kimo

Privacy Policy

Last updated: 31 August 2026


Short version: Kimo is built around phone numbers, so it has to be careful by default. We process the number you look up, your own number (on Android, to detect it; not on iOS), and only the contacts you choose to let us read — and we process them so the service works, not to build advertising profiles. Spam scores are community-driven and stored against the number, not against you. We do not sell your data.

This is the public Privacy Policy for Kimo. If you live in Türkiye, your rights under the KVKK are detailed below and override any less-protective statement here.

1. Who we are (the data controller)

Kimo (package com.nevranizamoglu.kimo) is made and operated by Nevra Nizamoğlu, based in Türkiye. We act as the data controller for the personal data described in this policy under the KVKK (the Turkish Personal Data Protection Law, 6698 sayılı Kanun), and as controller (or co-controller where required) under the GDPR for users in the EEA and the United Kingdom.

For any privacy question, complaint, or rights request, contact nevranizamoglu@gmail.com. We respond within 30 days at the latest.

2. What we collect and why

Kimo runs without an account. There is no email, no phone-number-as-identity, and no login. The data the app handles falls into a small number of buckets, each used only to deliver a specific feature:

3. Phone numbers you look up

When you type a Turkish phone number into the app, we send that number to our backend (a self-hosted PocketBase instance) and return whatever we know about it — a label, a community spam score, a category. We log the lookup event with a hashed, rotated, anonymous identifier for your device so we can enforce daily limits (e.g. ten free lookups a day on the free tier) and tell abuse patterns from genuine mistakes.

We never ask for or store your phone number as part of the lookup unless you look up your own number, which the app can detect automatically on Android.

4. Crowdsourced spam data

When a user reports a number as spam, the report is stored against the number, not the reporter. A report bundles the number, a category (e.g. insurance scam, sales call, market survey), an optional short note, the current community score, and a count. We do not attach the reporter's identity to a report.

If you would like your number hidden from Kimo's public record entirely, see §10.

5. Your own number (Android only)

On Android, the app asks for the phone state permission (READ_PHONE_STATE) only to read your own number, so you don't have to type it in and so the app can recognise when an incoming call is from yourself. We read the number once, on first launch, store a hash of it locally, and use it only to suppress the "is this you?" prompt. We do not transmit your own phone number to our backend.

iOS does not expose the device's own number through public APIs, so the iOS version never reads it.

6. Your address book (only if you grant access)

With your explicit consent, the app reads your address book so it can show you which numbers in a search result are already in your contacts versus unknown. We process the contact list on the device to produce this in-app overlay; your contacts are not uploaded to our backend in identifiable form. You can revoke this at any time in your device settings, and Kimo will continue to work for one-off lookups.

7. Call log (Android, deferred)

Kimo's Android manifest declares the call-log permission so a future version can mark unknown numbers directly in your recent-calls list. The current public release does not request or read the call log, and the permission is not used. We will update this section before any version that does.

8. Purchases

If you subscribe, payment is handled entirely by Apple or Google. We never see your card number, billing address, or full name on the receipt. We use RevenueCat to verify subscriptions across reinstalls — it receives an anonymous install identifier, the product identifier, transaction identifier and date, and your store country. We do not pass your name, email, or contacts to RevenueCat.

9. Analytics

The public release ships without third-party analytics. If we add analytics later, this section will be updated before they ship, and an in-app notice will announce the change.

10. Your rights (KVKK and beyond)

Depending on where you live, you have the right to:

To exercise any of these, email nevranizamoglu@gmail.com with the address or number the request concerns. We will acknowledge within 30 days and complete the request or explain why a particular right does not apply.

If you want your phone number hidden from Kimo's public record: email us from a verifiable address with the number. We will add it to an internal suppression list; new spam reports against it will not be published, and existing score data for the number will be hidden.

Complaints. You also have the right to complain to the Kişisel Verileri Koruma Kurumu (Turkish Personal Data Protection Board, kvkk.gov.tr), or to your local supervisory authority under the GDPR.

11. Legal basis for processing

Where the KVKK or GDPR applies, our legal bases are:

12. International transfers

Kimo's primary backend lives in Türkiye. The third-party providers named in §14 process data globally — including the United States and the EEA — under their own standard contractual clauses or equivalent safeguards.

13. Security

No system is perfectly secure. If you have a security concern, please email nevranizamoglu@gmail.com with "security" in the subject.

14. Third-party services

ServicePurposePrivacy policy
Apple App StoreiOS payment processinghttps://www.apple.com/legal/privacy
Google PlayAndroid payment processinghttps://policies.google.com/privacy
RevenueCatSubscription verificationhttps://www.revenuecat.com/privacy
PocketBaseSelf-hosted lookup and spam-score backendhttps://pocketbase.io/docs/

15. Children

Kimo is intended for users 13 and over. We do not knowingly collect personal information from children. If you are a parent with a concern, please email nevranizamoglu@gmail.com.

16. Changes

If we change this policy we will update the date at the top and publish the new version at this address. Significant changes will be announced in the app and via the same email contact above.

17. Contact

Nevra Nizamoğlu — Türkiye nevranizamoglu@gmail.com

For KVKK-specific requests, write "KVKK request" in the subject line — that flags it as a formal data-subject request.